Shirofune-Security
610dd92905
Document outgoing NTLM audit behavior in changelogs
2026-09-19 02:04:59 +09:00
Zach Mathis (田中ザック)
6efda1e018
Merge pull request #390 from Shirofune-Security/feat/364-shared-audit-profiles
...
Document shared versioned audit-policy profiles in changelogs
2026-09-19 14:55:51 +09:00
Zach Mathis (田中ザック)
fbb84dc998
Merge pull request #391 from Shirofune-Security/feat/369-missing-audit-controls
...
Document six native audit controls in changelogs
2026-09-19 14:35:41 +09:00
田中ザック Isaac Mathis
27957e859f
Merge pull request #392 from Shirofune-Security/fix/365-configuration-results
...
Verify configuration outcomes with dry-run and recovery journaling
2026-09-19 14:06:12 +09:00
Zach Mathis (田中ザック)
6fd86f21ce
Merge pull request #389 from Shirofune-Security/fix/363-domain-ntlm-audit
...
Enable full domain NTLM auditing only on domain controllers
2026-09-19 13:13:01 +09:00
Shirofune-Security
e4266424c7
Document shared versioned audit-policy profiles in changelogs
2026-09-19 01:45:21 +09:00
Shirofune-Security
27cb050be7
Document six native audit controls in changelogs
2026-09-19 01:27:57 +09:00
Shirofune-Security
7d2117ebba
Fix audit applicability, NTLM value types, and native exit verification
2026-09-19 00:36:38 +09:00
Shirofune-Security
71215ab498
Merge main and preserve NTLM output regression coverage
2026-09-19 00:28:55 +09:00
Shirofune-Security
e574dcde60
Document verified configuration and recovery features in changelogs
2026-09-19 00:23:17 +09:00
Shirofune-Security
bf69494bd9
Report configuration-only audit states without rule coverage inference
2026-09-18 22:59:25 +09:00
Shirofune-Security
571f9ff51f
Document domain NTLM audit correction in changelogs
2026-09-18 22:53:31 +09:00
Shirofune-Security
9bd56a0840
Scope integration test doubles alongside script-local helpers
2026-09-18 22:16:11 +09:00
Shirofune-Security
4c2193964e
Keep deferred configuration callbacks in script scope on PowerShell 5.1
2026-09-18 22:13:58 +09:00
Shirofune-Security
595f123327
Test unsupported dry-run rejection and NTLM policy races safely
2026-09-18 22:12:30 +09:00
Shirofune-Security
60e6552823
Integrate standalone outgoing NTLM fresh-state safeguards
2026-09-18 22:10:17 +09:00
Shirofune-Security
fa5141755b
Reject unsupported dry runs and preserve freshly observed NTLM restrictions
2026-09-18 22:10:17 +09:00
Shirofune-Security
bc9e098c81
Recheck outgoing NTLM enforcement after confirmation
2026-09-18 22:09:37 +09:00
Shirofune-Security
ebd8d14d04
Include read-only Windows CLI profile smoke checks
2026-09-18 22:06:06 +09:00
Shirofune-Security
6392c9bd58
Merge commit 'f4f9c33' into feat/369-missing-audit-controls
2026-09-18 22:05:30 +09:00
Shirofune-Security
aa34a0360b
Integrate minimum-policy and role-detection safeguards
2026-09-18 22:05:29 +09:00
Shirofune-Security
d96f04dcef
Integrate profile masks metadata and dry runs with verified execution
2026-09-18 22:05:25 +09:00
Shirofune-Security
f4f9c33de2
Exercise real audit CLI export in Windows read-only smoke
2026-09-18 22:05:13 +09:00
Shirofune-Security
c7b4e47925
Merge commit 'd3160a2' into feat/369-missing-audit-controls
2026-09-18 22:05:01 +09:00
Shirofune-Security
d3160a2033
Preserve additional minimum audit flags and reject unknown CA roles
2026-09-18 22:04:43 +09:00
Shirofune-Security
24dcbdd852
Refresh native audit control evidence assertions for integration
2026-09-18 22:01:53 +09:00
Shirofune-Security
7fc5c0034f
Retain profile evidence and prerequisites in integration results
...
# Conflicts:
# WELA.ps1
2026-09-18 22:01:04 +09:00
Shirofune-Security
a6cef75c12
Verify source attribution and prerequisites in native control results
2026-09-18 22:00:52 +09:00
Shirofune-Security
4432090a6f
Merge commit '98d37fb' into feat/369-missing-audit-controls
2026-09-18 22:00:40 +09:00
Shirofune-Security
4a192d7a13
Integrate six missing native audit controls with profile execution
2026-09-18 22:00:30 +09:00
Shirofune-Security
d480db5a76
Integrate versioned audit profiles with verified configuration
...
# Conflicts:
# .github/workflows/release.yml
# WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security
98d37fbf37
Retain policy prerequisites and evidence in apply results
2026-09-18 21:59:59 +09:00
Shirofune-Security
5be186f952
Add six missing native audit subcategories with source-specific masks
2026-09-18 21:58:33 +09:00
Shirofune-Security
f2dc28a66b
Test composed NTLM policy journaling dry runs and failures
2026-09-18 21:58:06 +09:00
Shirofune-Security
e0518b41ed
Refresh configuration regression harness for integration
2026-09-18 21:57:42 +09:00
Shirofune-Security
f5a19a45fd
Integrate verified configuration results for review
...
# Conflicts:
# WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security
bf82f2c458
Clear expected child failure codes after regression assertions
2026-09-18 21:56:01 +09:00
Shirofune-Security
ee7a0e2216
Unify advanced audit policy audit, plan and configure profiles
2026-09-18 21:54:38 +09:00
Shirofune-Security
eb3232faf5
Read audit masks through Windows API and preserve missing registry parents
2026-09-18 21:53:44 +09:00
Shirofune-Security
7979019ef0
Integrate domain NTLM audit role scoping for review
...
# Conflicts:
# WELA.ps1
2026-09-18 21:51:44 +09:00
Shirofune-Security
8cb4804334
Integrate outgoing NTLM audit-only behavior for review
2026-09-18 21:51:29 +09:00
Shirofune-Security
d51c37258f
Use explicit PowerShell shells in regression workflow
2026-09-18 21:49:46 +09:00
Shirofune-Security
ca54b5cf74
Use explicit PowerShell shells in regression workflow
2026-09-18 21:49:46 +09:00
Shirofune-Security
36c4b4018f
Run configuration checks with explicit PowerShell shells
2026-09-18 21:49:46 +09:00
Shirofune-Security
1ae4930438
Verify configure changes and propagate per-control failures
2026-09-18 21:48:27 +09:00
Shirofune-Security
16d88a6f1e
Enable full domain NTLM auditing only on domain controllers
2026-09-18 21:46:28 +09:00
Shirofune-Security
ade681ff1b
Make outgoing NTLM configuration audit-only by default
2026-09-18 21:46:06 +09:00
Zach Mathis (田中ザック)
8ef938f096
Merge pull request #361 from Shirofune-Security/feat/targeted-object-audit-sacls
...
Add 'configure-sacl': targeted File System/Registry audit SACLs for detection (no global auditing)
2026-09-14 20:32:50 +09:00
Shirofune-Security and Claude Opus 4.8
10c1bcaac7
Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
...
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.
Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
Shirofune-Security and Claude Opus 4.8
570b9565d1
CHANGELOG: note configure additions ( #361 )
...
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:32:51 +09:00